CVE-2024-41628: Severalnines Clustercontrol

High severity, CVSS 7.5. EPSS: 6.5% chance of exploitation in the next 30 days.

Directory Traversal vulnerability in Severalnines Cluster Control 1.9.8 before 1.9.8-9778, 2.0.0 before 2.0.0-9779, and 2.1.0 before 2.1.0-9780 allows a remote attacker to include and display file content in an HTTP request via the CMON API.

Affected products

  • Severalnines Clustercontrol: from 1.9.8, before 1.9.8-9778 (fixed in 1.9.8-9778); from 2.0.0, before 2.0.0-9779 (fixed in 2.0.0-9779); from 2.1.0, before 2.1.0-9780 (fixed in 2.1.0-9780)

Published 2024-07-26. Last modified 2026-07-09.